Dashboards & Visualizations

Json logs not parsing properly.

mahesh27
Communicator

Hi All, We have a json logs where few logs are not parsing properly. When i check internal logs its shows that truncate value exceed the default 10000 bytes, so i tried increasing truncate value to 40000, but still logs are not parsing correctly.

the logs length is around  26000.

props used:

[app:json:logs]
SHOULD_LINEMERGE=true
LINE_BREAKER=([\r\n]+)
CHARSET=UTF-8
TIMEPREFIX=\{\"timestamp"\:\"
KV_MODE=json
TRUNCATE=40000

 

 

Labels (1)
0 Karma

nmohammed
Builder

Try adding a limits.conf with the following

[kv]
maxchars = 40000
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mahesh27 ,

try to add INDEXED_EXTRACTIONS = JSON to your props.conf

Ciao.

Giuseppe

0 Karma

mahesh27
Communicator

Hi @gcusello, sorry we have a limitation not to use that is there any other way 

0 Karma

gcusello
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...